SmarterMail WT-2026-0001 Authentication Bypass Enables Admin Takeover and RCE
SmarterTools SmarterMail patched a critical authentication bypass tracked as WT-2026-0001 after researchers reported that attackers can reset the system administrator password without authentication by abusing the /api/v1/auth/force-reset-password endpoint. The flaw stems from logic in SmarterMail.Web.Api.AuthenticationController.ForceResetPassword that permits anonymous access and trusts a user-supplied boolean (IsSysAdmin); when set to true, the code path updates an admin account’s password without validating the old password or enforcing authorization checks.
Both reporting indicate the issue is actively exploited in the wild, with observed exploitation occurring within days of the vendor patch (including reports of activity as soon as two days after release). Once an attacker resets the admin password, they can take over the mail server and leverage built-in administrative capabilities to execute OS commands, effectively achieving remote code execution (RCE) and full compromise of affected SmarterMail deployments; the patch was released as Build 9511 following responsible disclosure by watchTowr Labs researchers Piotr Bazydlo and Sina Kheirkhah.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
6 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-23760 is assigned to the SmarterMail vulnerability
The SmarterMail authentication bypass was assigned CVE-2026-23760, covering versions prior to Build 9511. The CVE record was received on 2026-01-22 and documented the issue as an authentication bypass in the password reset API leading to full administrative compromise.
watchTowr publicly discloses WT-2026-0001 and exploitation details
On 2026-01-22, watchTowr Labs publicly disclosed the SmarterMail flaw, describing how unauthenticated attackers could set IsSysAdmin=true, reset an admin password, and then abuse features such as Volume Mounts to achieve SYSTEM-level remote code execution. The disclosure also included evidence of active exploitation and a proof-of-concept path to shell access.
Forum report indicates admin password was changed via the vulnerable endpoint
A SmarterMail forum post dated 2026-01-17 suggested the vulnerable endpoint had been used to change an administrator password in the wild. This became an early public indicator of active exploitation.
Attackers begin exploiting the flaw after patch release
Evidence from logs and later reporting indicates attackers started exploiting unpatched SmarterMail systems within about 48 hours of the patch, likely by reverse engineering Build 9511. The activity involved resetting administrator passwords through the force-reset-password endpoint.
SmarterTools releases SmarterMail Build 9511 patch
SmarterTools released SmarterMail Build 9511 to fix the password-reset API issue by adding old-password validation for administrator resets. Release notes reportedly described the update only as containing critical security fixes.
watchTowr reports SmarterMail auth bypass to SmarterTools
watchTowr Labs reported a critical SmarterMail authentication-bypass flaw, later tracked as WT-2026-0001, to the vendor. BleepingComputer says the report was made on 2026-01-08.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
6 references tracked. Mallory keeps watching after this page renders.
SmarterMail flaw under active attack post-patch | SC Media
scworld.com
Open sourceSmarterMail auth bypass flaw now exploited to hijack admin accounts
bleepingcomputer.com
Open sourceAttackers Reverse‑Engineer Patch to Exploit SmarterMail Admin Bypass in the Wild
cybersecuritynews.com
Open sourceCVE-2026-23760 - SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
cvefeed.io
Open source"Enjoy Your Admin Access": Critical SmarterMail RCE Exploited in the Wild
securityonline.info
Open sourceSmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release
thehackernews.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


